Privacy Policy
Last updated: 11/30/2025
1. Introduction
ShinRAG ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using ShinRAG, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1. Information You Provide
We collect information that you provide directly to us, including:
- Account Information: Name, email address, and other information you provide during registration
- Content: Datasets, documents, prompts, and other content you upload or create using the Service
- API Keys: Third-party API keys you provide (encrypted and stored securely)
- Payment Information: Billing address and payment method information (processed by third-party payment processors)
- Communications: Information you provide when contacting us for support or inquiries
2.2. Automatically Collected Information
We automatically collect certain information when you use the Service:
- Usage Data: Token usage, API calls, feature usage, and other metrics
- Log Data: IP address, browser type, device information, access times, and pages viewed
- Cookies and Tracking: Information collected through cookies and similar tracking technologies
- Error Reports: Technical information about errors or crashes
2.3. Third-Party Information
We may receive information from third-party services you connect to the Service, such as authentication providers (e.g., Clerk) and payment processors (e.g., Lemon Squeezy).
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide, maintain, and improve the Service
- To process transactions and manage your subscription
- To authenticate your identity and manage your account
- To enforce usage limits and subscription tiers
- To send you service-related notifications and updates
- To respond to your inquiries and provide customer support
- To detect, prevent, and address technical issues and security threats
- To comply with legal obligations and enforce our Terms of Service
- To analyze usage patterns and improve our Service (using aggregated, anonymized data)
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal bases:
- Contract Performance: To fulfill our contract with you and provide the Service
- Legitimate Interests: To improve our Service, ensure security, and prevent fraud
- Consent: Where you have provided consent for specific processing activities
- Legal Obligations: To comply with applicable laws and regulations
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
5.1. Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Cloud hosting and infrastructure providers
- Authentication services (e.g., Clerk)
- Payment processors (e.g., Lemon Squeezy)
- Analytics and monitoring services
- Customer support tools
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
5.2. AI Model Providers
When you use platform-provided API keys, your queries and data may be processed by third-party AI model providers (e.g., OpenAI). These providers have their own privacy policies and terms of service.
5.3. Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Respond to valid legal requests
5.4. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of sensitive data in transit and at rest
- Secure storage of API keys using industry-standard encryption
- Access controls and authentication mechanisms
- Regular security assessments and updates
- Employee training on data protection
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as necessary to:
- Provide the Service to you
- Comply with legal obligations
- Resolve disputes and enforce our agreements
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes. Some information may remain in backup systems for a limited period.
8. Your Rights (GDPR and CCPA)
Depending on your location, you may have the following rights regarding your personal information:
8.1. Access
You have the right to request access to your personal information and receive a copy of the data we hold about you.
8.2. Rectification
You have the right to request correction of inaccurate or incomplete personal information.
8.3. Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal information, subject to legal retention requirements.
8.4. Restriction of Processing
You have the right to request restriction of processing of your personal information in certain circumstances.
8.5. Data Portability
You have the right to receive your personal information in a structured, commonly used, and machine-readable format.
8.6. Objection
You have the right to object to processing of your personal information based on legitimate interests.
8.7. Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time.
8.8. Opt-Out (CCPA)
If you are a California resident, you have the right to opt-out of the sale of personal information (we do not sell personal information).
To exercise these rights, please contact us at privacy@shinrag.com. We will respond to your request within 30 days (or as required by applicable law).
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.
When we transfer personal data from the EEA or UK to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission.
10. Children's Privacy
Our Service is not intended for children under the age of 16 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete such information.
11. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Maintain your session and authenticate your identity
- Remember your preferences and settings
- Analyze usage patterns and improve the Service
- Provide security features
You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the Service.
12. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email or through the Service.
14. Data Protection Officer
If you have questions or concerns about our data processing practices, you can contact our Data Protection Officer at: dpo@shinrag.com
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: privacy@shinrag.com
For GDPR-related inquiries, you also have the right to lodge a complaint with your local data protection authority.